REDHAT-BUG-2458635: High severity Bouncy Castle BC-JAVA vulnerability
Published Apr 15, 2026
·Updated
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). Non-constant time comparisons risk private key leakage in FrodoKEM.
This issue affects BC-JAVA: from 2.17.3 before 1.84.
Affected Software
1 affected component
Bouncy Castle BC-JAVA
Event History
Apr 15, 2026
Data Sourced
via Red Hat·10:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2458635?
The severity of REDHAT-BUG-2458635 is classified as high with a score of 7.
2
How do I fix REDHAT-BUG-2458635?
To fix REDHAT-BUG-2458635, update Bouncy Castle BC-JAVA to a version later than 2.17.3 and before 1.84.
3
What vulnerability does REDHAT-BUG-2458635 address?
REDHAT-BUG-2458635 addresses a covert timing channel vulnerability in the BC-JAVA core related to non-constant time comparisons.
4
What impact does REDHAT-BUG-2458635 have on private keys?
REDHAT-BUG-2458635 poses a risk of private key leakage in FrodoKEM due to the timing channel vulnerability.
5
Which versions of BC-JAVA are affected by REDHAT-BUG-2458635?
BC-JAVA versions from 2.17.3 before 1.84 are affected by REDHAT-BUG-2458635.